2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67688 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module.... |
| CVE-2026-67687 | HIGH | 8.8 | 0.3% | Aug 6, 2026 | Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol... |
| CVE-2026-67622 | CRITICAL | 9.9 | 0.2% | Aug 6, 2026 | Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th... |
| CVE-2026-67621 | HIGH | 7.6 | 0.2% | Aug 6, 2026 | Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf... |
| CVE-2026-67434 | HIGH | 7.3 | 0.7% | Aug 6, 2026 | PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.... |
| CVE-2026-67422 | HIGH | 7.5 | 0.6% | Aug 6, 2026 | pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ... |
| CVE-2026-65400 | CRITICAL | 9.8 | 0.3% | Aug 6, 2026 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS... |
| CVE-2026-64677 | MEDIUM | 5.9 | 0.8% | Aug 6, 2026 | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ... |
| CVE-2026-64665 | HIGH | 8.1 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ... |
| CVE-2026-64664 | MEDIUM | 4.3 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont... |
| CVE-2026-64663 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup... |
| CVE-2026-64662 | MEDIUM | 6.5 | 0.3% | Aug 6, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont... |
| CVE-2026-64655 | LOW | 2.1 | 0.3% | Aug 6, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify builds the certificate S... |
| CVE-2026-64654 | MEDIUM | 5.3 | 0.7% | Aug 6, 2026 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex... |
| CVE-2026-64653 | MEDIUM | 5.1 | 0.5% | Aug 6, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat... |
| CVE-2026-64652 | LOW | 3.3 | 0.1% | Aug 6, 2026 | GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte... |
| CVE-2026-63725 | HIGH | 8.6 | 0.3% | Aug 6, 2026 | sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta... |
| CVE-2026-63637 | HIGH | 8.6 | 0.2% | Aug 6, 2026 | Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.... |
| CVE-2026-62857 | HIGH | 8.8 | 0.2% | Aug 6, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the... |
| CVE-2026-61632 | MEDIUM | 5.3 | 0.4% | Aug 6, 2026 | PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2... |
| CVE-2026-5857 | CRITICAL | 9.2 | 0.5% | Aug 6, 2026 | Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ... |
| CVE-2026-5856 | HIGH | 7.1 | 0.3% | Aug 6, 2026 | Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack... |
| CVE-2026-5855 | HIGH | 8.7 | 0.5% | Aug 6, 2026 | Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt... |
| CVE-2026-5336 | MEDIUM | 6.8 | 0.4% | Aug 6, 2026 | The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren... |
| CVE-2026-54717 | MEDIUM | 5.4 | 0.2% | Aug 6, 2026 | Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now